CVE-2014-3528

EUVD-2014-3525
Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:P/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
Affected Products (NVD)
VendorProductVersion
opensuseopensuse
12.3
opensuseopensuse
13.1
apachesubversion
1.0.0
apachesubversion
1.0.1
apachesubversion
1.0.2
apachesubversion
1.0.3
apachesubversion
1.0.4
apachesubversion
1.0.5
apachesubversion
1.0.6
apachesubversion
1.0.7
apachesubversion
1.0.8
apachesubversion
1.0.9
apachesubversion
1.1.0
apachesubversion
1.1.1
apachesubversion
1.1.2
apachesubversion
1.1.3
apachesubversion
1.1.4
apachesubversion
1.2.0
apachesubversion
1.2.1
apachesubversion
1.2.2
apachesubversion
1.2.3
apachesubversion
1.3.0
apachesubversion
1.3.1
apachesubversion
1.3.2
apachesubversion
1.4.0
apachesubversion
1.4.1
apachesubversion
1.4.2
apachesubversion
1.4.3
apachesubversion
1.4.4
apachesubversion
1.4.5
apachesubversion
1.4.6
apachesubversion
1.5.0
apachesubversion
1.5.1
apachesubversion
1.5.2
apachesubversion
1.5.3
apachesubversion
1.5.4
apachesubversion
1.5.5
apachesubversion
1.5.6
apachesubversion
1.5.7
apachesubversion
1.5.8
apachesubversion
1.6.0
apachesubversion
1.6.1
apachesubversion
1.6.2
apachesubversion
1.6.3
apachesubversion
1.6.4
apachesubversion
1.6.5
apachesubversion
1.6.6
apachesubversion
1.6.7
apachesubversion
1.6.8
apachesubversion
1.6.9
apachesubversion
1.6.10
apachesubversion
1.6.11
apachesubversion
1.6.12
apachesubversion
1.6.13
apachesubversion
1.6.14
apachesubversion
1.6.15
apachesubversion
1.6.16
apachesubversion
1.6.17
apachesubversion
1.6.18
apachesubversion
1.6.19
apachesubversion
1.6.20
apachesubversion
1.6.21
apachesubversion
1.6.23
apachesubversion
1.7.0
apachesubversion
1.7.1
apachesubversion
1.7.2
apachesubversion
1.7.3
apachesubversion
1.7.4
apachesubversion
1.7.5
apachesubversion
1.7.6
apachesubversion
1.7.7
apachesubversion
1.7.8
apachesubversion
1.7.9
apachesubversion
1.7.10
apachesubversion
1.7.11
apachesubversion
1.7.12
apachesubversion
1.7.13
apachesubversion
1.7.14
apachesubversion
1.7.15
apachesubversion
1.7.16
apachesubversion
1.7.17
apachesubversion
1.8.0
apachesubversion
1.8.1
apachesubversion
1.8.2
apachesubversion
1.8.3
apachesubversion
1.8.4
apachesubversion
1.8.5
apachesubversion
1.8.6
apachesubversion
1.8.7
apachesubversion
1.8.8
apachesubversion
1.8.9
canonicalubuntu_linux
12.04
canonicalubuntu_linux
14.04
applexcode
6.1.1
redhatenterprise_linux_desktop
6.0
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_hpc_node
6.0
redhatenterprise_linux_hpc_node
7.0
redhatenterprise_linux_server
6.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_server_eus
6.6.z:z
redhatenterprise_linux_workstation
6.0
redhatenterprise_linux_workstation
7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
subversion
bookworm
1.14.2-4
fixed
bullseye
1.14.1-3+deb11u1
fixed
bullseye (security)
1.14.1-3+deb11u1
fixed
sid
1.14.4-2
fixed
squeeze
no-dsa
trixie
1.14.4-2
fixed
wheezy
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
subversion
lucid
ignored
precise
Fixed 1.6.17dfsg-3ubuntu3.4
released
trusty
Fixed 1.8.8-1ubuntu3.1
released
Common Weakness Enumeration